Privacy policy
Last updated: 24 June 2026
1. General information
SquadStats ("the Platform", "we") is a sports management system (AMS) for clubs, teams and athletes. This policy describes what data we collect, how we use it and how we protect it, on both the web app and the mobile app.
By using the Platform you accept this Privacy policy. If you do not agree, do not use it.
2. Data we collect
Depending on the user’s role, we collect:
- Name, surname and email address.
- Profile photo (optional, chosen by the user).
- Basic biometric data: height, weight and date of birth (optional).
- Daily wellness data: sleep quality, mood, muscle soreness, motivation and stress, on a 1–5 scale.
- Training load: sessions, duration and rate of perceived exertion (RPE).
- Injuries and their tracking: diagnosis, treatment, progress and rehabilitation messages.
- Fitness test results and match performance statistics.
- Training attendance and, if the coaching staff logs it, a brief reason for an absence.
- Notification preferences and the device’s push-notification tokens.
Sports data belongs to the organisation (club) the user is linked to.
3. Legal basis and consent
Processing of identifying and usage data is based on the user’s consent and on the sports organisation’s legitimate interest in managing its athletes’ performance (art. 6 GDPR).
Wellness, training load, injury and rehabilitation data are health-related data (special category under art. 9 GDPR). They are processed on the basis of the data subject’s explicit consent (art. 9.2.a GDPR), with reinforced safeguards: data minimisation, per-organisation access control (RLS), and encryption in transit and at rest.
SquadStats’s AI sends Google (Gemini) only the match-statistics document the coaching staff uploads (Excel, CSV, PDF or a photo) or the match video it is asked to analyse; Google acts as a data processor and does not train its models on this data.
For underage users, consent from a parent or legal guardian is required before creating the account.
4. How we use the data
- Show the team’s wellness and load status to the coaching staff.
- Generate alerts when an athlete shows risk indicators.
- Record and display physical and sporting progress.
- Send notifications the user controls from Settings → Notifications (alerts, reminders and summaries).
- Let the athlete see only their own data.
We do not use the data for advertising, and we do not sell it or share it with third parties for commercial purposes.
5. Who can see the data
- Coaching staff and club owners: the data of the athletes in their organisation.
- Athletes: only their own data.
- Other organisations: no access under any circumstances (database-level organisation isolation).
6. Data processors (sub-processors)
To run the Platform we use providers that process data on our behalf:
- Clerk — authentication and account management (name, email, credentials).
- Supabase — database and file storage.
- Resend — transactional emails (invitations, alerts, summaries).
- Stripe — subscription payment processing (web version only). Stripe processes payment data; SquadStats does not store card data.
- Vercel — web app hosting.
- Expo — push notification delivery on the mobile app.
- Google (Gemini API) — only if your club uses the AI stats import or the AI-assisted video analysis: it processes the statistics document (Excel, CSV, PDF or a photo) or the match video the coaching staff points it to, to map columns, players or produce the requested analysis. Google processes this data as a processor and does not use it to train its models.
All of them operate under data processing agreements and security measures equivalent to those described here.
7. Storage and security
Data is stored on secure servers, encrypted in transit (TLS) and at rest. Access is protected by authentication and by row-level security policies (RLS) that isolate each organisation.
To allow offline use, the mobile app temporarily stores on the device any data pending sync (for example, a wellness entry logged without coverage). This data is stored encrypted (AES-256) in the operating system’s secure storage and syncs automatically once the connection is restored.
8. Retention and deletion
Data is kept for as long as the organisation has an active account. When an account or organisation is deleted, data is removed from active systems immediately and from backups within 30 days at most.
You can delete your account yourself from Settings → “Delete my account” (web and mobile), or follow the instructions at app.squadstats.dev/legal/eliminar-cuenta. An athlete can also request deletion of their data from their organisation’s admin, or by writing to soporte@squadstats.dev.
9. Your rights (GDPR and local regulations)
You have the right to:
- Access your personal data.
- Correct inaccurate data (you can edit your name, email and profile from Settings).
- Request deletion of your data ("right to be forgotten").
- Portability: download your data in a structured format from Settings → “Export my data”.
- Object to processing or request its restriction in certain circumstances.
- Lodge a complaint with the competent supervisory authority (in Spain, the AEPD).
To exercise any of these rights, write to soporte@squadstats.dev.
10. Minors
The Platform is not intended for children under 13. For athletes between 13 and 18, the organisation is responsible for obtaining parental or guardian consent before creating the account.
11. Changes to this policy
We may update this policy. We will notify relevant changes through the Platform or by email. Continued use implies acceptance of the updated policy.
12. Contact
Email: soporte@squadstats.dev
Web: https://squadstats.dev